# Kibana

**URL:** https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=7

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 8

---

## [Need help with simple agregation](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274)

<div class="topic-metadata">

**Author:** [@marjue](https://discuss.elastic.co/u/marjue)\
**Replies:** 4\
**Last updated:** [November 7, 2025, 4:21am UTC](https://discuss.elastic.co/t/need-help-with-simple-agregation/383274 "2025-11-07T04:21:41Z")

</div>

Hello I need help in a simple case but I’m too stupid. There is an index with simple monitoring data. The main fields are: service\_name (text) service\_status (text) service\_time (date) Every 5 minutes a new state f…

---

## [How to get rid of dotted lines seen in Kibana maps](https://discuss.elastic.co/t/how-to-get-rid-of-dotted-lines-seen-in-kibana-maps/383240)

<div class="topic-metadata">

**Author:** [@ramenon](https://discuss.elastic.co/u/ramenon)\
**Replies:** 1\
**Last updated:** [November 6, 2025, 1:54pm UTC](https://discuss.elastic.co/t/how-to-get-rid-of-dotted-lines-seen-in-kibana-maps/383240 "2025-11-06T13:54:56Z")

</div>

Hello , Good day. I wanted to ask if there’s any way to remove the dotted line between the points that I have plotted in Kibana Maps , I tried toggling every option available for the Layers but it just doesn’t go away. …

---

## [Convert UTC timestamp to local timezone](https://discuss.elastic.co/t/convert-utc-timestamp-to-local-timezone/383049)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 1\
**Last updated:** [November 1, 2025, 5:30am UTC](https://discuss.elastic.co/t/convert-utc-timestamp-to-local-timezone/383049 "2025-11-01T05:30:16Z")

</div>

Hello, can someone help me to figure out how to convert UTC based timestamp in Kibana watcher to local timezone timestamp? When the watcher is executed, it has execution timestamp. It is very confusing as the timestamp…

---

## [Deleting users from elasticsearch but still appear on assignees](https://discuss.elastic.co/t/deleting-users-from-elasticsearch-but-still-appear-on-assignees/383116)

<div class="topic-metadata">

**Author:** [@naverlyn](https://discuss.elastic.co/u/naverlyn)\
**Replies:** 2\
**Last updated:** [November 1, 2025, 4:58am UTC](https://discuss.elastic.co/t/deleting-users-from-elasticsearch-but-still-appear-on-assignees/383116 "2025-11-01T04:58:00Z")

</div>

Hi, Is this intentional to delete users but still appear on assignees panel? For example, i have user named “hytam” on elasticsearch (I previously deleted already) but still appearing on assignees. In users page, there…

---

## [ES|QL Basic Help](https://discuss.elastic.co/t/es-ql-basic-help/383107)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 30, 2025, 6:21pm UTC](https://discuss.elastic.co/t/es-ql-basic-help/383107 "2025-10-30T18:21:15Z")

</div>

Hello, I did a STATS count = COUNT\_DISTINCT(event.outcome) by host.name. And it works, the only issue I wish I could keep the metadata information about the host? Is there a way to do this??

---

## [Kibana Internal API's via Python Request](https://discuss.elastic.co/t/kibana-internal-apis-via-python-request/383073)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 6\
**Last updated:** [October 30, 2025, 1:11pm UTC](https://discuss.elastic.co/t/kibana-internal-apis-via-python-request/383073 "2025-10-30T13:11:09Z")

</div>

Is it possible to interact with Kibana's internal API's via Python? Do I need to add something to the header of the request besides {'kbn-xsrf': 'true'} My specific use case is to be able to assign ML jobs to a specific…

---

## [Data view - how to delete](https://discuss.elastic.co/t/data-view-how-to-delete/383037)

<div class="topic-metadata">

**Author:** [@Marek\_Galbavy](https://discuss.elastic.co/u/Marek_Galbavy)\
**Replies:** 6\
**Last updated:** [October 30, 2025, 8:43am UTC](https://discuss.elastic.co/t/data-view-how-to-delete/383037 "2025-10-30T08:43:19Z")

</div>

Hi how can i delete data views which are created by elastic? eg Latest cloud…. etc if i delete data views which i dont want they are created again. thx

---

## [How to create a network utilization of inbound traffic and outbound like solarwind](https://discuss.elastic.co/t/how-to-create-a-network-utilization-of-inbound-traffic-and-outbound-like-solarwind/383078)

<div class="topic-metadata">

**Author:** [@Syed\_Yaseen\_Arham](https://discuss.elastic.co/u/Syed_Yaseen_Arham)\
**Replies:** 2\
**Last updated:** [October 30, 2025, 8:07am UTC](https://discuss.elastic.co/t/how-to-create-a-network-utilization-of-inbound-traffic-and-outbound-like-solarwind/383078 "2025-10-30T08:07:03Z")

</div>

we have field called ifInOctets which incremental field and its values in bytes. ifSpeed is in GBPs polling inverval 120 seconds My Formula ((counter\_rate(max(ifInOctets))\*8)/60)/average(ifSpeed) i tried to this but…

---

## [Fleet policy settings "Agent logging to files" & "Agent log level" does not work](https://discuss.elastic.co/t/fleet-policy-settings-agent-logging-to-files-agent-log-level-does-not-work/382982)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 2\
**Last updated:** [October 30, 2025, 7:26am UTC](https://discuss.elastic.co/t/fleet-policy-settings-agent-logging-to-files-agent-log-level-does-not-work/382982 "2025-10-30T07:26:51Z")

</div>

Hello, I’m replacing Metricbeats with Elastic-Agent on multiple servers so i can manage them through UI, but I noticed that some options are not working like "Agent logging to files" & "Agent log level", you have to di…

---

## [No logs in discovery](https://discuss.elastic.co/t/no-logs-in-discovery/383044)

<div class="topic-metadata">

**Author:** [@NeedHelp](https://discuss.elastic.co/u/NeedHelp)\
**Replies:** 1\
**Last updated:** [October 29, 2025, 4:39am UTC](https://discuss.elastic.co/t/no-logs-in-discovery/383044 "2025-10-29T04:39:09Z")

</div>

Hello, I have installed the following on three VMs: Elasticsearch: 192.168.101.9 Kibana: 192.168.101.7 OPNsense: 192.168.101.8 Next, I started the Fleet Server and installed it on Kibana (192.168.101.7). I t…

---

## [ES|QL date histogram?](https://discuss.elastic.co/t/es-ql-date-histogram/383029)

<div class="topic-metadata">

**Author:** [@kmp](https://discuss.elastic.co/u/kmp)\
**Replies:** 4\
**Last updated:** [October 28, 2025, 3:32pm UTC](https://discuss.elastic.co/t/es-ql-date-histogram/383029 "2025-10-28T15:32:44Z")

</div>

I’m really trying to start to use ES|QL… About six months ago, I generated some queries (saved search sessions) and was wondering why (unlike the Classic search) there was no date histogram displayed. I was playing aro…

---

## [User access privilege on specific dashboard](https://discuss.elastic.co/t/user-access-privilege-on-specific-dashboard/383007)

<div class="topic-metadata">

**Author:** [@Kumar\_6](https://discuss.elastic.co/u/Kumar_6)\
**Replies:** 3\
**Last updated:** [October 27, 2025, 10:04am UTC](https://discuss.elastic.co/t/user-access-privilege-on-specific-dashboard/383007 "2025-10-27T10:04:38Z")

</div>

Hi Team, I would like to know if this feature is available in Elastic Kibana. I have four dashboards within a single space and want to provide access to different users. For example, one user should have access only to …

---

## [Popular fields are not persistent or shared across users in Kibana (popularity count resets after reload)](https://discuss.elastic.co/t/popular-fields-are-not-persistent-or-shared-across-users-in-kibana-popularity-count-resets-after-reload/382677)

<div class="topic-metadata">

**Author:** [@shojiiii](https://discuss.elastic.co/u/shojiiii)\
**Replies:** 2\
**Last updated:** [October 27, 2025, 12:44am UTC](https://discuss.elastic.co/t/popular-fields-are-not-persistent-or-shared-across-users-in-kibana-popularity-count-resets-after-reload/382677 "2025-10-27T00:44:34Z")

</div>

Hello Elasticsearch community, I'm currently facing an issue where "popular fields" in Kibana are not persistent or consistent across users. When I reload the Discover view or log in as a different user, the popularity…

---

## [Kibana pod won't start with fleet enabled in hyphenated namespace](https://discuss.elastic.co/t/kibana-pod-wont-start-with-fleet-enabled-in-hyphenated-namespace/382863)

<div class="topic-metadata">

**Author:** [@smashley](https://discuss.elastic.co/u/smashley)\
**Replies:** 3\
**Last updated:** [October 25, 2025, 2:02am UTC](https://discuss.elastic.co/t/kibana-pod-wont-start-with-fleet-enabled-in-hyphenated-namespace/382863 "2025-10-25T02:02:12Z")

</div>

I have an existing ES cluster for logging/SIEM and wish to enable fleet/agent. The cluster is deployed via ECK on kubernetes in namespace ‘elasticsearch-enterprise’ to differentiate it from our basic licensed clusters. T…

---

## [Ingest pipeline disable](https://discuss.elastic.co/t/ingest-pipeline-disable/379095)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [October 24, 2025, 11:58am UTC](https://discuss.elastic.co/t/ingest-pipeline-disable/379095 "2025-10-24T11:58:54Z")

</div>

Is there any possibility to temporarily disable an ingest pipeline during development? I.e for testing purposes. Thanks!

---

## [Kibana Visualization date\_histogram weekly start day: Sunday (Start of Week) in Dashboard](https://discuss.elastic.co/t/kibana-visualization-date-histogram-weekly-start-day-sunday-start-of-week-in-dashboard/382877)

<div class="topic-metadata">

**Author:** [@josh\_tran](https://discuss.elastic.co/u/josh_tran)\
**Replies:** 2\
**Last updated:** [October 24, 2025, 10:15am UTC](https://discuss.elastic.co/t/kibana-visualization-date-histogram-weekly-start-day-sunday-start-of-week-in-dashboard/382877 "2025-10-24T10:15:01Z")

</div>

I want weekly date\_histogram function to start on Sunday in Kibana dashboards, but they currently start on Monday (ISO week). I’m using Kibana Lens with Elasticsearch 9.0.4. I’ve tried adjusting dateFormat:dow settings t…

---

## [Problems with displaying the map in the dashboard](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771)

<div class="topic-metadata">

**Author:** [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Replies:** 11\
**Last updated:** [October 24, 2025, 3:06am UTC](https://discuss.elastic.co/t/problems-with-displaying-the-map-in-the-dashboard/382771 "2025-10-24T03:06:38Z")

</div>

I installed the official Elastic integration to collect 365 logs. Using the dashboard that provides the integration, I see nothing in the map section (see image). Has anyone encountered this issue? Or does anyone know ho…

---

## [Fatal error on Kibana startup - 8.19.5 - Windows Server 2025 - Error: Cannot find module '../series\_functions/undefined'](https://discuss.elastic.co/t/fatal-error-on-kibana-startup-8-19-5-windows-server-2025-error-cannot-find-module-series-functions-undefined/382920)

<div class="topic-metadata">

**Author:** [@markus](https://discuss.elastic.co/u/markus)\
**Replies:** 3\
**Last updated:** [October 23, 2025, 2:36pm UTC](https://discuss.elastic.co/t/fatal-error-on-kibana-startup-8-19-5-windows-server-2025-error-cannot-find-module-series-functions-undefined/382920 "2025-10-23T14:36:16Z")

</div>

I’m currently trying to upgrade my ELK Stack from 8.17.8 to 8.19.5. OS is Windows Server 2025 When starting Kibana it fails with the following error log: \[2025-10-23T15:19:48.349+02:00\]\[FATAL\]\[root\] Reason: Cannot fin…

---

## [Generate PDF puts timing in light grey](https://discuss.elastic.co/t/generate-pdf-puts-timing-in-light-grey/382887)

<div class="topic-metadata">

**Author:** [@jorism-ict](https://discuss.elastic.co/u/jorism-ict)\
**Replies:** 1\
**Last updated:** [October 23, 2025, 10:10am UTC](https://discuss.elastic.co/t/generate-pdf-puts-timing-in-light-grey/382887 "2025-10-23T10:10:54Z")

</div>

When creating a PDF Report from a dashboard, using “Generate PDF”, the PDF is generated, but the title of the report, including the selected timeframe (top -center of the generated pdf) is printed in light grey. We had c…

---

## [Dynamic dropdown not changing](https://discuss.elastic.co/t/dynamic-dropdown-not-changing/382735)

<div class="topic-metadata">

**Author:** [@Sanderb](https://discuss.elastic.co/u/Sanderb)\
**Replies:** 2\
**Last updated:** [October 23, 2025, 9:39am UTC](https://discuss.elastic.co/t/dynamic-dropdown-not-changing/382735 "2025-10-23T09:39:02Z")

</div>

Hi all, For my Kibana dashboard I want to have 2 dropdowns (of type ES|QL control), one with the API’s and another one with the endpoint corresponding to the API selected in the first dropdown. So for example, if API ==…

---

## [PagerDuty connector action breaks on \\n present in any data inserted with Mustache in custom\_details section](https://discuss.elastic.co/t/pagerduty-connector-action-breaks-on-n-present-in-any-data-inserted-with-mustache-in-custom-details-section/382806)

<div class="topic-metadata">

**Author:** [@tofijak](https://discuss.elastic.co/u/tofijak)\
**Replies:** 2\
**Last updated:** [October 21, 2025, 1:27pm UTC](https://discuss.elastic.co/t/pagerduty-connector-action-breaks-on-n-present-in-any-data-inserted-with-mustache-in-custom-details-section/382806 "2025-10-21T13:27:06Z")

</div>

Hi, We are using the PagerDuty connector and have a rule that triggers on any error logs. We want to be able to pass the errors messages in the custom\_details attribute, which is required to valid JSON. This is what we…

---

## [Kibana: Cannot update rule](https://discuss.elastic.co/t/kibana-cannot-update-rule/382845)

<div class="topic-metadata">

**Author:** [@Cristian\_Pereyra](https://discuss.elastic.co/u/Cristian_Pereyra)\
**Replies:** 2\
**Last updated:** [October 21, 2025, 11:54am UTC](https://discuss.elastic.co/t/kibana-cannot-update-rule/382845 "2025-10-21T11:54:55Z")

</div>

Hello everyone, I hope you're doing well. I'm creating a rule of type "Elasticsearch query" that uses a connector to a Python microservice, which then sends an email. The rule works fine. However, when I try to update …

---

## [Kibana download relevant files](https://discuss.elastic.co/t/kibana-download-relevant-files/382843)

<div class="topic-metadata">

**Author:** [@kucerp21](https://discuss.elastic.co/u/kucerp21)\
**Replies:** 8\
**Last updated:** [October 20, 2025, 10:07pm UTC](https://discuss.elastic.co/t/kibana-download-relevant-files/382843 "2025-10-20T22:07:01Z")

</div>

We use Kibana as a UI for searching and analyzing some data that we store in Elasticsearch. The individual data entries in Elasticsearch have S3 identifiers stored with them for relevant files. We need to enable our user…

---

## [Predict Full Disk Usage Date](https://discuss.elastic.co/t/predict-full-disk-usage-date/382847)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [October 20, 2025, 8:32pm UTC](https://discuss.elastic.co/t/predict-full-disk-usage-date/382847 "2025-10-20T20:32:45Z")

</div>

Hello, How can I predict the date the disk will be full like this: I tried Elastic ML and used it to forecast, but I am not sure how to produce a date that can be added to a dashboard?

---

## [ES|QL RLIKE](https://discuss.elastic.co/t/es-ql-rlike/382831)

<div class="topic-metadata">

**Author:** [@Balu](https://discuss.elastic.co/u/Balu)\
**Replies:** 2\
**Last updated:** [October 20, 2025, 1:24pm UTC](https://discuss.elastic.co/t/es-ql-rlike/382831 "2025-10-20T13:24:18Z")

</div>

We are a little confused here, playing with ES|QL and RLIKE in Discover:. This one works and returns paths like \\\\?\\C:\\Windows\\CSC\\v2.0.6\\namespace\\example.com\\DFS\\Homes\\User\\Downloads\\evil.exe | WHERE file.path RLIKE …

---

## [Trouble with privileges about Kibana Actions](https://discuss.elastic.co/t/trouble-with-privileges-about-kibana-actions/382340)

<div class="topic-metadata">

**Author:** [@Alberto\_Russo](https://discuss.elastic.co/u/Alberto_Russo)\
**Replies:** 2\
**Last updated:** [October 16, 2025, 9:34am UTC](https://discuss.elastic.co/t/trouble-with-privileges-about-kibana-actions/382340 "2025-10-16T09:34:37Z")

</div>

I had install Security Onion in standalone mode, and I tryed to create a new rule in Kibana. But if I want to assign an action to this rule he said “Cannot create rule actions. You do not have “Read” permissions for the …

---

## [Anomaly Detection - Can' Forecast on Influencer](https://discuss.elastic.co/t/anomaly-detection-can-forecast-on-influencer/382754)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 1\
**Last updated:** [October 15, 2025, 9:58pm UTC](https://discuss.elastic.co/t/anomaly-detection-can-forecast-on-influencer/382754 "2025-10-15T21:58:19Z")

</div>

Hello, I created a anomaly detection job on memory utilization. I am using host.name as an influencer I see the forecast but when I run it doesn’t allow me to focus on an influencer? My goal: I am trying to predict…

---

## [Kibana DevTools stuck on autocomplete when typing a simple GET](https://discuss.elastic.co/t/kibana-devtools-stuck-on-autocomplete-when-typing-a-simple-get/382631)

<div class="topic-metadata">

**Author:** [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Replies:** 2\
**Last updated:** [October 15, 2025, 2:00pm UTC](https://discuss.elastic.co/t/kibana-devtools-stuck-on-autocomplete-when-typing-a-simple-get/382631 "2025-10-15T14:00:51Z")

</div>

Kibana version: 8.19.4 Tested on different browsers both in normal and private mode When you have already a lot of queries in dev tools (let’s say 10000 lines) and want to add another by simply typing GET the browser i…

---

## [Granting read access to ingest pipelines in Kibana](https://discuss.elastic.co/t/granting-read-access-to-ingest-pipelines-in-kibana/373065)

<div class="topic-metadata">

**Author:** [@cekay](https://discuss.elastic.co/u/cekay)\
**Replies:** 3\
**Last updated:** [October 15, 2025, 10:28am UTC](https://discuss.elastic.co/t/granting-read-access-to-ingest-pipelines-in-kibana/373065 "2025-10-15T10:28:13Z")

</div>

Hi, We have users that we want to be able to access the information about the configured ingest pipelines in Kibana. I gave them the cluster privilege read\_pipeline, but that does not help with seeing the pipelines in Ki…

---

## [Share URL long or short depending on role?](https://discuss.elastic.co/t/share-url-long-or-short-depending-on-role/382697)

<div class="topic-metadata">

**Author:** [@Balu](https://discuss.elastic.co/u/Balu)\
**Replies:** 1\
**Last updated:** [October 15, 2025, 6:38am UTC](https://discuss.elastic.co/t/share-url-long-or-short-depending-on-role/382697 "2025-10-15T06:38:35Z")

</div>

Hey, our users noticed that the URLs you can get using the share feature (in Discover for example) are short for some users and long for others This seems to depend on the assigned roles of the users. Our superusers w…

[Previous page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=6)

[Next page](https://discuss.elastic.co/c/elastic-stack/kibana/7.md?page=8)
